Skip to content

test(deps): bump the npm group with 3 updates - #1468

Merged
Ron (rjaegers) merged 2 commits into
mainfrom
dependabot/npm_and_yarn/npm-556dcda51e
Sep 21, 2026
Merged

Ron (rjaegers) merged 2 commits into
mainfrom
dependabot/npm_and_yarn/npm-556dcda51e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm group with 3 updates: @playwright/test, @types/node and playwright-bdd.

Updates @playwright/test from 1.62.1 to 1.63.0

Release notes

Sourced from @​playwright/test's releases.

v1.63.0

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock. Tests that share a lock name never run concurrently, across files, workers and projects, while everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group. Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments, and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API

... (truncated)

Commits
  • 1b025d7 chore: mark v1.63.0 (#42569)
  • 0b9956d cherry-pick(#42568): docs(test): mark test.step subtitle option as since v1.63
  • 13dbf10 cherry-pick(#42552): docs: release notes for v1.63
  • e93b64e cherry-pick(#42566): feat(test): add subtitle option to test.step (#42567)
  • 2b7a5f2 test: response.body() for content-encoding:identity (#42537)
  • 648a67c fix(mcp): create parent directories for explicitly named files (#42540)
  • 7894f56 docs(mcp): clarify how tool file names are resolved (#42538)
  • 52900a1 devops: restore npm publishing from GitHub Actions (#42550)
  • 8c47f59 docs(csharp): fix nonexistent method names in guide examples (#42507)
  • bd6e552 chore(video): emit frames with real timestamps, drop frame number quantizatio...
  • Additional commits viewable in compare view

Updates @types/node from 26.4.1 to 26.5.1

Commits

Updates playwright-bdd from 9.2.0 to 9.2.1

Release notes

Sourced from playwright-bdd's releases.

v9.2.1

  • fix: support Playwright 1.63 by removing obsolete experimental component testing dependencies (#331)
Changelog

Sourced from playwright-bdd's changelog.

[9.2.1] - 2026-09-06

  • fix: support Playwright 1.63 by removing obsolete experimental component testing dependencies (#331)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm group with 3 updates: [@playwright/test](https://github.com/microsoft/playwright), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [playwright-bdd](https://github.com/vitalets/playwright-bdd).


Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `@types/node` from 26.4.1 to 26.5.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `playwright-bdd` from 9.2.0 to 9.2.1
- [Release notes](https://github.com/vitalets/playwright-bdd/releases)
- [Changelog](https://github.com/vitalets/playwright-bdd/blob/main/CHANGELOG.md)
- [Commits](vitalets/playwright-bdd@v9.2.0...v9.2.1)

---
updated-dependencies:
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@types/node"
  dependency-version: 26.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: playwright-bdd
  dependency-version: 9.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 18, 2026
@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-base:edgeghcr.io/philips-software/amp-devcontainer-base:pr-1468

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 80.88 MB 80.88 MB +56 B (+0%) 🔼
linux/arm64 79.18 MB 79.18 MB 3 B (0%) 🔽

@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 23 0 0 0.34s
✅ DOCKERFILE hadolint 4 0 0 0.45s
✅ JSON npm-package-json-lint yes no no 0.52s
✅ JSON prettier 46 8 0 0 1.02s
✅ JSON v8r 46 0 0 14.76s
✅ MARKDOWN markdownlint 13 0 0 0 2.04s
✅ MARKDOWN markdown-table-formatter 13 0 0 0 0.3s
✅ REPOSITORY betterleaks yes no no 3.29s
✅ REPOSITORY checkov yes no no 23.76s
✅ REPOSITORY git_diff yes no no 0.09s
✅ REPOSITORY grype yes no no 79.85s
⚠️ REPOSITORY osv-scanner yes 1 4 2.68s
✅ REPOSITORY secretlint yes no no 1.42s
✅ REPOSITORY syft yes no no 4.75s
✅ REPOSITORY trivy yes no no 12.52s
✅ REPOSITORY trivy-sbom yes no no 0.51s
✅ REPOSITORY trufflehog yes no no 5.1s
⚠️ SPELL lychee 119 1 0 9.37s
✅ YAML prettier 36 0 0 0 1.12s
✅ YAML v8r 36 0 0 12.7s
✅ YAML yamllint 36 0 0 1.4s

Detailed Issues

⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........154
🔗 Unique.........126
✅ Successful.....148
⏳ Timeouts.........0
🔀 Redirected......19
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden

Hint: Followed 19 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 1 error
warning: Package 'brace-expansion@5.0.7' is vulnerable to 'CVE-2026-14257' (also known as 'GHSA-mh99-v99m-4gvg').
 = CVE-2026-14257: brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
 = ### Summary
   
   `expand()` bounds the *number* of results it produces (the `max` option,
   `100_000` by default) but not their *length*. By chaining many brace groups,
   an attacker keeps the result count under `max` while making every result grow
   with the number of groups. Building `max` long results — plus the intermediate
   arrays combined at each brace group — exhausts memory and crashes the Node
   process with an **uncatchable** out-of-memory error. `try/catch` around
   `expand()` does not help: the fatal error terminates the process.
   
   A ~7.5 KB input (`'{a,b}'.repeat(1500)`) is enough to crash a default Node
   process.
   
   ### Details
   
   For `N` chained brace groups such as `'{a,b}'.repeat(N)`:
   
   - the result count is `2^N`, immediately capped at `max` (`100_000`), so the
     `max` protection appears to hold, but
   - each result is `N` characters long, so the total output size is
     `max × N` characters, which grows without bound in `N`.
   
   `expand_` combines each brace set with the fully-expanded tail:
   
   ```js
   const post = m.post.length ? expand_(m.post, max, false) : ['']
   ...
   for (let j = 0; j < N.length; j++) {
     for (let k = 0; k < post.length && expansions.length < max; k++) {
       const expansion = pre + N[j] + post[k]   // grows one group longer per level
       ...
       expansions.push(expansion)
     }
   }

The loop guard expansions.length < max limits how many strings are built, but
nothing limits how long they get. Each recursion level materializes another
array of up to max strings, one character longer than the level below, and —
because V8 represents pre + N[j] + post[k] as a cons-string (rope) that
references post[k] — those intermediate strings stay reachable through the
whole chain. Memory therefore scales with max × N.

Measured on 5.0.7 ('{a,b}'.repeat(N), default max):

groups (N) input bytes result count peak RSS
20 100 100,000 ~80 MB
50 250 100,000 ~214 MB
100 500 100,000 ~409 MB
300 1,500 100,000 ~1,148 MB
1500 7,500 OOM crash

Proof of concept

const { expand } = require('brace-expansion')

// ~7.5 KB input — crashes the process with a fatal, uncatchable OOM:
//   FATAL ERROR: ... JavaScript heap out of memory
try {
  expand('{a,b}'.repeat(1500))
} catch (e) {
  // never reached — the process is already dead
}

Impact

Any application that passes attacker-influenced strings to
brace-expansion.expand() — directly, or transitively via minimatch / glob
brace patterns — can be crashed by a small request. Because the failure is a
fatal V8 out-of-memory error rather than a thrown exception, it cannot be caught
and it takes down the whole worker/process, denying service.

Remediation

Upgrade to a patched release. The fix bounds the total number of characters a
single expand() call may accumulate (EXPANSION_MAX_LENGTH, default
4_000_000, configurable via a new maxLength option), applied inside the
output-building loops so intermediate arrays are bounded too. Once the limit is
reached, output is truncated — consistent with how max already truncates —
instead of growing without bound. The limit sits well above any realistic
expansion (100,000 results hitting max measure ~1M characters), so legitimate
input is unaffected.

After the fix, '{a,b}'.repeat(1500) returns a bounded, truncated result in
~0.7 s using ~340 MB and never crashes, including under a constrained 512 MB
heap.

The fix bounds memory but the algorithm still rebuilds intermediate arrays at
each level (roughly O(N × maxLength) work on this input class). A streaming
rewrite that produces output in O(total output size) can be a non-urgent
follow-up.

If immediate upgrade isn't possible, avoid passing untrusted input to
expand() / glob brace patterns, or pass a small explicit max and
maxLength.

warning: Package 'brace-expansion@5.0.7' is vulnerable to 'CVE-2026-69152' (also known as 'GHSA-rgw5-rvv9-x895').
= CVE-2026-69152: brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
= ### Summary

The maxLength mitigation added in 5.0.8 for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are combined, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an uncatchable out-of-memory error, so try/catch around expand() does not help.

A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.

Details

maxLength was enforced in combine(), the single place output grows. Two arrays are built before combine() runs, and neither was bounded.

1. Comma alternatives accumulate without a running total (memory exhaustion)

Each alternative in {a,b,c,...} is expanded by its own recursive expand_() call, so each receives a full, independent maxLength allowance. The results were then concatenated into a single values array with no cumulative limit:

values = []
for (let j = 0; j < n.length; j++) {
  values.push.apply(values, expand_(n[j], max, maxLength, false))
}

acc = combine(acc, pre, values, max, maxLength, ...)

With A alternatives, values can reach A * maxLength characters before combine() gets a chance to truncate it. At the default maxLength of 4,000,000 and 400 alternatives, that is well past any default heap.

2. Padded sequences ignore maxLength while generating (CPU exhaustion)

expandSequence() was bounded by max (the result count) but never consulted maxLength. A padded sequence's element width follows the input, so {0...01..100000} with a wide pad generates max elements, each as wide as the input, only for combine() to discard all but a handful.

Memory stays flat here, because V8 represents the padded strings as cons-strings, which is likely why this path was not caught alongside the original issue. The cost is time: work proportional to max * width.

pad width input bytes results kept time (5.0.8) time (patched)
20,000 20 KB 199 ~7.3 s ~20 ms
100,000 100 KB 39 ~32 s ~20 ms
400,000 400 KB 9 ~124 s ~18 ms

Output is byte-identical before and after the fix; only the wasted work is removed.

Proof of concept

Memory exhaustion, against 5.0.8:

import { expand } from 'brace-expansion'

const part = '{' + '0'.repeat(50) + '1..100000}'
const input = '{' + Array(400).fill(part).join(',') + '}'  // ~25 KB

try {
  expand(input)
} catch (e) {
  // never reached - the process is already dead
}
FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory
Aborted

Event-loop stall, against 5.0.8:

import { expand } from 'brace-expansion'

// ~400 KB input, returns 9 results after roughly two minutes of blocking CPU
expand('{' + '0'.repeat(400_000) + '1..100000}')

Impact

Denial of service. Any application that passes attacker-controlled input to expand(), directly or transitively through a glob or pattern-matching library, can be remotely crashed or stalled. The out-of-memory variant terminates the process and cannot be handled with try/catch.

Applications already on 5.0.8 are affected: the 5.0.8 mitigation does not cover these paths.

Patches

Both intermediate arrays are now bounded as they are built, using the same max and maxLength limits already applied in combine():

  • values tracks a running result count and character length while alternatives are appended, and stops once either bound is reached.
  • expandSequence() accepts maxLength and stops generating once the sequence's own characters reach it.

As with the existing limits, output is truncated rather than allowed to grow without bound, which matches how max already behaves. The defaults sit well above any realistic expansion, so legitimate input is unaffected.

Workarounds

If upgrading is not immediately possible, avoid passing untrusted input to expand() or to glob brace patterns, or pass an explicitly small max and maxLength.

Note that a small maxLength alone was not sufficient on affected versions: it was applied per alternative rather than cumulatively, which is the root of the first issue above.

Credits

The memory-exhaustion bypass was reported by Alessio Della Libera, CEO & Co-founder at Numyra.

The sequence-generation issue was found while verifying that report.

warning: Package 'bare-metal@0.2.5' is vulnerable to 'RUSTSEC-2026-0110'.
= RUSTSEC-2026-0110: bare-metal is deprecated
= The bare-metal crate has been deprecated and archived.

For Mutex and CriticalSection, see the critical-section crate instead.

warning: Package 'bare-metal@0.2.5' is vulnerable to 'RUSTSEC-2026-0110'.
= RUSTSEC-2026-0110: bare-metal is deprecated
= The bare-metal crate has been deprecated and archived.

For Mutex and CriticalSection, see the critical-section crate instead.

warning: 4 warnings emitted


</details>

See detailed reports in [MegaLinter artifacts](https://github.com/philips-software/amp-devcontainer/actions/runs/35589928537)

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:
- [oxsecurity/megalinter/flavors/salesforce@v10.1.0](https://megalinter.io/10.1.0/flavors/salesforce/) (58 linters)


Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining `FLAVOR_SUGGESTIONS: false`)

  - Documentation: [Custom Flavors](https://megalinter.io/10.1.0/custom-flavors/)
  - Command: `npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R`

[![MegaLinter is provided by OX Security](https://raw.githubusercontent.com/oxsecurity/megalinter/main/docs/assets/images/ox-banner.png)](https://www.ox.security/?ref=megalinter)
Show us your support by [**starring ⭐ the repository**](https://github.com/oxsecurity/megalinter)

<!-- megalinter: github-comment-reporter workflow='Linting & Formatting' jobid='linter' -->

@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Test Results

 25 files  + 21   25 suites  +21   9m 0s ⏱️ + 8m 58s
 53 tests + 44   53 ✅ + 44  0 💤 ±0  0 ❌ ±0 
229 runs  +193  229 ✅ +193  0 💤 ±0  0 ❌ ±0 

Results for commit efb1a6b. ± Comparison against base commit 6189711.

♻️ This comment has been updated with latest results.

@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-docs:edgeghcr.io/philips-software/amp-devcontainer-docs:pr-1468

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 212.34 MB 212.34 MB +426 B (+0%) 🔼
linux/arm64 208.87 MB 208.87 MB +258 B (+0%) 🔼

@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-rust:edgeghcr.io/philips-software/amp-devcontainer-rust:pr-1468

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 436.79 MB 436.79 MB +662 B (+0%) 🔼
linux/arm64 387.07 MB 387.07 MB 209 B (0%) 🔽

@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-rust:edgeghcr.io/philips-software/amp-devcontainer-embedded-rust:pr-1468

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 503.54 MB 503.54 MB 95 B (0%) 🔽
linux/arm64 453.48 MB 453.48 MB +67 B (+0%) 🔼

@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:edgeghcr.io/philips-software/amp-devcontainer-cpp:pr-1468

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 404.95 MB 404.95 MB +1.29 kB (+0%) 🔼
linux/arm64 385.72 MB 385.72 MB 726 B (0%) 🔽

@rjaegers
Ron (rjaegers) deployed to acceptance-testing September 21, 2026 10:48 — with GitHub Actions Active
@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-cpp:edgeghcr.io/philips-software/amp-devcontainer-embedded-cpp:pr-1468

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 607.1 MB 607.1 MB +1 kB (+0%) 🔼
linux/arm64 587.15 MB 587.16 MB +1.21 kB (+0%) 🔼

@rjaegers
Ron (rjaegers) added this pull request to the merge queue Sep 21, 2026
Merged via the queue into main with commit 5dc99d6 Sep 21, 2026
81 checks passed
@rjaegers
Ron (rjaegers) deleted the dependabot/npm_and_yarn/npm-556dcda51e branch September 21, 2026 11:18
@github-actions

Copy link
Copy Markdown
Contributor

Pull Request Report (#1468)

Static measures

Description Value
Number of added lines 27
Number of deleted lines 30
Number of changed files 2
Number of commits 2
Number of reviews 1
Number of comments (w/o review comments) 9
Number of reviews that contains a comment to resolve 0
Number of reviews that requested a change from the author 0
Number of reviews that approved the Pull Request 1
Get the total number of participants of a Pull Request 5

Time related measures

Description Value
PR lead time (from creation to close of PR) 3.1 Days
Time that was spend on the branch before the PR was created 1 Sec
Time that was spend on the branch before the PR was merged 3.1 Days
Time to merge after last review 38.4 Min

Status check related measures

Description Value
Total runtime for last status check run (Workflow for PR) 1.4 Hours
Total time spend in last status check run on PR 17.1 Min

@github-actions

Copy link
Copy Markdown
Contributor

🎉 Hooray! The changes in this pull request went live with the release of v8.3.0 🎉

This branch was successfully deployed

1 active deployment
acceptance-testing efb1a6b9 Deployed Sep 21, 2026 by rjaegers via Build → Push → Test / 🍨 cpp / 🏗️ / Acceptance Test #2502
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant